National Institute of Standards and Technology (NIST)

In January, the General Services Administration’s (GSA) Office of the Chief Information Security Officer issued a new procedural guide, CIO-IT Security-21-112 Rev. 1, that sets expectations for protecting Controlled Unclassified Information (CUI) when it resides in nonfederal contractor systems. Although the document is internal guidance, it creates an approval framework that may soon determine

On July 22, 2025, the National Institute of Standards and Technology (NIST) issued proposed updates to NIST SP 800-53 Controls on Secure and Reliable Patches designed to “address software resiliency, developer testing, secure logging, least privilege for functions and tools, deployment management of updates, software integrity and validation, delineation of roles and responsibilities between organizations